Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49169] Use after free in DNS Server allows an authorized attacker to execute code over a network.
Use after free in DNS Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49170] Insufficient granularity of access control in Windows StateRepository API allows an authorized attac…
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48571] Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48572] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48581] Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to ele…
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49162] Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege…
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-45646] Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker…
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47296] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47632] Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate pr…
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48564] Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over…
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42975] Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu…
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42982] Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized a…
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-44800] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40378] Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (L…
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40400] Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n…
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42900] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
14/07/2026
CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
14/07/2026
CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).